API-key setup checklist
Create the key in the venue's official interface and review every permission before saving it.
- use a separate key for MatrixLink;
- enable read-only or trade only when required;
- keep withdrawals disabled at all times;
- apply an IP allowlist and expiry when available.
Responding to suspected exposure
Revoke the key at the venue immediately, inspect order and login history, close active sessions, and create a replacement only after finding the cause.
Updated: 2026-07-18
Frequently asked questions
Why is a trade-only key still sensitive?
An attacker could place harmful orders, alter positions, or use thin markets to transfer value indirectly.
Should an API secret be sent to support?
No. Never share it in chats, tickets, or screenshots; revoke the key if exposure is possible.